You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 19, 2016

Regulation of Domestic Debit Card Transactions in Thailand

Asian Banking & Finance

Back in 2012, Thailand’s Electronic Transactions Commission issued regulations that mandated domestic processing of domestic debit card transactions with debit cards issued in Thailand. It granted a grace period of one year for service providers to meet the new requirements. This was a policy goal that had been discussed and pursued for some time, with policymakers highlighting the cost savings that would be yielded by domestic processing, rather than offshore processing.

New regulations were issued in March 2016, which were published in the Government Gazette  in April. The changes in those regulations in relation to processing domestic debit card transactions mainly provided greater specificity and rules around outsourcing and requests for temporary exemptions from parts of the regulations.

More recently, in July, amendments were made to the regulations, and these were published in the Government Gazette  in August. Among other things, the new regulations refer to a chip card standard for debit cards, and they state that the standard is to be issued and imposed by the Bank of Thailand through discussions with the Thai Bankers’ Association, the Association of International Banks in Thailand, and the Council of State-Owned Financial Institutions.

Financial institutions that issue debit cards will be required to issue cards meeting this chip card standard, and the cards must be issued to use debit card networks in Thailand, unless an issuer utilizes its own system for processing the transactions. The regulations also affect consumer protection, in that they require issuers to provide users with information and details about the costs of each type of debit card that is sufficient, clear, and correct, so that users can use the service properly for their own purposes.

Where an issuer issues a card that is accepted on more than one network, at least one of those networks must be a domestic debit card network. In working with multiple networks, regulations require an issuer to observe its agreements and take account of the principle of equality.

The regulations also impose new obligations on acquirers. Specifically, they are required to have equipment and systems to accept debit cards that meet the aforementioned chip card standard and that utilize local debit card networks. Importantly, acquirers are prohibited from restricting the rights of merchants to use any debit card networks. They are also required to provide merchants with clear and accurate information on fees and services. In addition, where multi-network cards are processed, an acquirer must not charge any additional fees other than those for the network that is actually used.

Aside from issuers and acquirers, the regulations also set out additional requirements for service providers that provide switching service, clearing service, and settlement service. These service providers are required to arrange their systems to support debit cards on all debit card networks or to connect their systems with those of other service providers that provide switching, clearing, and settlement. In relation to cards that can be accepted on multiple networks, a service provider must not interfere with a merchant’s right to select a debit card network.

The new requirements are to be enforced from February next year. Consistent with earlier regulations, if an issuer or acquirer is unable to meet the new requirements, it can apply to the Bank of Thailand for additional time to come into compliance—up to an additional 180 days.  Also, for those cards issued prior to enforcement of the new requirements, they can continue to be used, but the issuer will eventually need to replace them with cards meeting the chip card standard by December 31, 2019.

These regulations follow an earlier announcement by the Bank of Thailand in May of this year that commercial banks in Thailand would, from May 16 onward, issue cards in conformity with the “Thai Bank Chip Card Standard,” which was established by the Thai Bankers’ Association. Last year, China UnionPay issued press releases about entering into a Chip Card Standard License Agreement with the Thai Bankers’ Association, which contemplated the adoption of China UnionPay’s chip card standard as “the standard of Thailand’s banking industry.” China UnionPay became a member of EMVCo in 2013, thus joining Visa, MasterCard, American Express, JCB, and Discover in the consortium that manages EMV standards (the technical standard for such chips). However, much has also been written about the compatibility problems between China UnionPay’s version of EMV, and the versions of EMV used by other card schemes such as MasterCard and Visa.

In referring to the chip card standard, the new regulations do not make specific reference to the China UnionPay standard, or any particular standard, for that matter. Moreover, in referring to the development of the chip card standard, the regulations make reference not only to discussions with the Thai Bankers’ Association, but also to the Association of International Banks in Thailand and the Council of State-Owned Financial Institutions, which is quite broad consultation.

China UnionPay is a major shareholder in Thailand Payment Network Co., Ltd. (TPN), established in 2014, which is one of the small number of companies that have been granted licenses necessary for providing switching and clearing services for domestic debit card transactions in Thailand. One can now see some debit cards issued by Bangkok Bank—the other major shareholder in TPN—that bear TPN branding, together with China UnionPay branding. In essence, TPN will compete with National ITMX Co., Ltd., which is owned by ten major banks in Thailand and has been providing local debit card switching services for some years.

As it now stands, most banks in Thailand issue Visa and MasterCard debit cards, each with EMV chips. It remains to be seen whether TPN and China UnionPay will become popular.  Customers like Visa and MasterCard because of their ease of acceptance, particularly when traveling overseas. In contrast, TPN has positioned itself as a low-cost provider for local transactions, which it says should enable merchants to accept TPN branded-cards for small transactions. Ultimately, more competition in the processing of domestic debit card transactions is good for merchants. Indeed, this has already prompted several banks to reduce their fees for debit card transactions. Thailand’s electronic payments landscape continues to excite.

RELATED INSIGHTS​ 

December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.